<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: correct TIME_FORMAT for time stamp in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/correct-TIME-FORMAT-for-time-stamp/m-p/498382#M138862</link>
    <description>&lt;P&gt;I gave it a shot unfortunately it didn't work.&lt;/P&gt;

&lt;P&gt;I have tried this also ( this is based on the &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.0/SearchReference/Commontimeformatvariables"&gt;splunk date time doc&lt;/A&gt; ) with no luck. Any other ideas?&lt;BR /&gt;
%b %e %Y %l:%M%p&lt;/P&gt;

&lt;P&gt;logs&lt;BR /&gt;
| xyz.a | 94 | 3100 | 2605 | 0 | 84 | | Dec 3 2019 1:01AM | destructive |&lt;BR /&gt;
| xyz.b| 94 | 45476 | 31607 | 1 | 70 | 166428 | Dec 3 2019 1:25AM | keeponline |&lt;BR /&gt;
| xtf.j| 94 | 3100 | 3044 | 0 | 98 | | Dec 3 2019 1:02AM | destructive |&lt;/P&gt;</description>
    <pubDate>Tue, 10 Dec 2019 00:25:38 GMT</pubDate>
    <dc:creator>Melstrathdee</dc:creator>
    <dc:date>2019-12-10T00:25:38Z</dc:date>
    <item>
      <title>correct TIME_FORMAT for time stamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/correct-TIME-FORMAT-for-time-stamp/m-p/498380#M138860</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I'm having trouble extracting the following timestamp for one source, is there someone here that can recommend what values to put into the $SPLUNK_HOME/etc/system/default/local file under the TIME_FORMAT attribute?&lt;/P&gt;

&lt;P&gt;Dec 3 2019 12:59AM &lt;/P&gt;

&lt;P&gt;I have set TIME_FORMAT to be %b %#d %Y %l:%M%p but it is ignoring the AM or PM&lt;/P&gt;

&lt;P&gt;I am getting an error could not use strptime to parse timestamp from | xyz.com | 94 | 2051 | 436 | 0 | 21 | | Dec 3 2019 12:59AM | destructive |&lt;/P&gt;

&lt;P&gt;and it is returning this is the timestamp 12/3/19 12:59:00.000 PM&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:12:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/correct-TIME-FORMAT-for-time-stamp/m-p/498380#M138860</guid>
      <dc:creator>Melstrathdee</dc:creator>
      <dc:date>2020-09-30T03:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: correct TIME_FORMAT for time stamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/correct-TIME-FORMAT-for-time-stamp/m-p/498381#M138861</link>
      <description>&lt;P&gt;in props.conf&lt;/P&gt;

&lt;P&gt;[yoursourcetype]&lt;BR /&gt;
TIME_FORMAT = %b %d %Y %I:%M%p&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 06:28:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/correct-TIME-FORMAT-for-time-stamp/m-p/498381#M138861</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2019-12-09T06:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: correct TIME_FORMAT for time stamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/correct-TIME-FORMAT-for-time-stamp/m-p/498382#M138862</link>
      <description>&lt;P&gt;I gave it a shot unfortunately it didn't work.&lt;/P&gt;

&lt;P&gt;I have tried this also ( this is based on the &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.0/SearchReference/Commontimeformatvariables"&gt;splunk date time doc&lt;/A&gt; ) with no luck. Any other ideas?&lt;BR /&gt;
%b %e %Y %l:%M%p&lt;/P&gt;

&lt;P&gt;logs&lt;BR /&gt;
| xyz.a | 94 | 3100 | 2605 | 0 | 84 | | Dec 3 2019 1:01AM | destructive |&lt;BR /&gt;
| xyz.b| 94 | 45476 | 31607 | 1 | 70 | 166428 | Dec 3 2019 1:25AM | keeponline |&lt;BR /&gt;
| xtf.j| 94 | 3100 | 3044 | 0 | 98 | | Dec 3 2019 1:02AM | destructive |&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 00:25:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/correct-TIME-FORMAT-for-time-stamp/m-p/498382#M138862</guid>
      <dc:creator>Melstrathdee</dc:creator>
      <dc:date>2019-12-10T00:25:38Z</dc:date>
    </item>
  </channel>
</rss>

